Trezor Phishing Ad and BTCPay Exploit Hit Bitcoin Users: Are Funds Safe?

  • A Google-sponsored ad led Bitcoin users to a Trezor phishing site, one victim says.
  • The flagged address received over 24 BTC, roughly $1.6 million, before emptying out.
  • BTCPay Server urged immediate updates to 2.4.2 over an actively exploited critical flaw.
Promo

A Trezor phishing scam promoted through a Google-sponsored ad has reportedly drained one user’s life savings, the victim says. Elsewhere, BTCPay Server shipped an emergency patch for a critical flaw already under active exploitation.

The two incidents landed within roughly 24 hours of each other. Neither touched the Bitcoin (BTC) protocol itself, yet both put user funds at direct risk.

Sponsored
Sponsored

Google Ad Funnels Victims to Trezor Phishing Site

The victim, posting on X (Twitter) under the name David, blamed a sponsored search ad on Thursday. Based on the report, the ad placed a counterfeit Trezor page, hosted on Google Sites, above the wallet maker’s real website.

Anyone who typed a recovery seed into the page handed attackers full control of their wallet.

On-chain data shows the wallet flagged in the report received 24.04 BTC across 80 transactions. That haul equals roughly $1.6 million at Bitcoin’s current price near $65,172. However, nearly all of it has moved on, leaving about 0.04 BTC behind.

Trezor said it escalated the case internally and reported the page for takedown.

“For everyone reading: always verify that you’re using the official Trezor website and never enter your wallet backup into a website or form,” the team urged.

Sponsored
Sponsored

The hardware itself was never breached. The attack worked because the seed left the device. The playbook echoes a fake Uniswap phishing site that drained $400,000 from wallets in May.

BTCPay Server Rushes Out Patch for Exploited Flaw

Meanwhile, BTCPay Server, open-source software that lets merchants accept bitcoin payments directly, issued its own warning on Friday.

Follow us on X to get the latest news as it happens

The team told operators to update to version 2.4.2 immediately or power servers down until they can.

“This release contains fix of a critical vulnerability that is being actively exploited. You need to update as fast as you can,” the project’s release notes state.

The Bitcoin Red Team, a volunteer security research group, reported the flaw to developers.

However, patching alone does not end the cleanup. Operators must also refresh macaroons, the access credentials Lightning nodes rely on, plus auth strings for other backends.

Anyone who generated a hot wallet inside BTCPay should move those funds and recreate it. Integrators should also update NBXplorer, a companion indexing tool, to version 2.6.10.

Why Both Incidents Matter for Bitcoin Self-Custody

One attack exploited trust in search ads. In contrast, the other exploited code running on merchant servers. Both sidestepped Bitcoin’s security model and hit the software and habits around it instead.

Phishing remains the costliest threat in crypto. January’s crypto theft losses reached about $400.3 million, and one phishing attack drove over 70% of that figure.

Google has yet to explain how the fraudulent ad cleared review. How fast the page comes down, and how many BTCPay operators patch in time, will shape the damage.


To read the latest cryptocurrency market analysis from BeInCrypto, click here.

Disclaimer

BeInCrypto is committed to unbiased, transparent reporting. This news article aims to provide accurate, timely information. However, readers are advised to verify facts independently and consult with a professional before making any decisions based on this content. Please note that our Terms and Conditions, Privacy Policy, and Disclaimers have been updated.

Sponsored
Sponsored